Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

61–70 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#61
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

Typo; they left out "door".

Re: Secret contract tied NSA and security industry pioneer

#63
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

Well NSA do have highly regarded crypto guys. And they do back the technology.

Truth in advertising, that.

Re: Secret contract tied NSA and security industry pioneer

#64

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

Heh...I certainly had a good chuckle at this comment. I don't honestly think that the NSA ever paid more than lip-service to the "war on terror". They've been doing the same job since long before Sept. 11, 2001. Before the "war on terror" it was the "cold war", there just happens to have been an awkward gap in between...

The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access to as much communication between non-US entities as humanly possible. What makes their job difficult is that, over the course of the last few decades, it's become increasingly the case that much of the communication between non-US entities travels via US-based channels using technology originated in the US. Somewhere along the line, when forced to balance "as much communication" and "non-US entities", the NSA clearly chose in favor of accessing those communications at any cost.

Re: Secret contract tied NSA and security industry pioneer

#65

Earlier quoted context omitted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

That's quite a leap from the information in that article.

Add it to all previous and you have some basis.

Companies that have been compromised[1] - MS, Apple, Facebook, Google, Yahoo, Carriers, Backbone providers - now they are going after security providers. From the big guys only Intel is standing. And that may as well be the next leak.

Also think if they subverted some of the big guys antiviral software - it runs at ring 0 usually.

[1] Blackmail, threats, bribes, lawful intercepts, warrants, NSLs

Re: Secret contract tied NSA and security industry pioneer

#66

Earlier quoted context omitted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

That's quite a leap from the information in that article.

That article is merely one piece of information in a long chain (Echelon, the Snowden revelations, Lavabit), and all of them add up to the conclusion that you better not trust any US-based/originated IT security system.

Re: Secret contract tied NSA and security industry pioneer

#67
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

As much as he can get under one's skin, and as much as he can be abrasive, and any number of other things, I trust his opinions on security and crypto.

He's rational to a fault--unfortunately, that means that when facts change he may be left with egg on his face. I don't think there's anything wrong with how he's handled this stuff.

Re: Secret contract tied NSA and security industry pioneer

#68
post #36
post #11

Earlier quoted context omitted.

I don't think this fiasco is related to the tokens but yes the tokens has other problems such that it didn't need NSA to break it.

I wasn't sure I skimmed half the article. It did have a giant image of one the tokens though.

It's a bad image, because it conveys an idea that's different from the story, but I can see why they used it -- from the general public's perspective the tokens are pretty much the most recognizable symbol of RSA.
Post reply on HN